🔴 CVE-2024-57968

Advantive VeraCore contains an unrestricted file upload vulnerability allowing authenticated remote attackers to upload malicious files to web-accessible directories. This vulnerability is actively exploited in the wild by the XE Group and listed in CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
9.9
CVSS Score
NETWORK
Attack Vector
Persistence
ATT&CK Tactic
T1505 — Server Software Component
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-02-03

Added to CISA KEV: 2025-03-10 35 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2024-57968 is a security vulnerability affecting Advantive VeraCore software, specifically versions prior to 2024.4.2.1 [1].

Active Exploitation and Threat Actor Usage
The vulnerability has been actively exploited in the wild as a zero-day. It has been linked to the cybercriminal outfit known as the XE Group, which was observed using this flaw—alongside CVE-2025-25181—to compromise servers [2]. Post-exploitation activity, including the use of webshells, was detected on a victim's IIS server hosting VeraCore software as early as November 2024 [2].
Attack Method and Requirements
  • Method: The vulnerability is an arbitrary file upload issue. It allows attackers to upload files to unintended directories, such as folders that are accessible to other users during web browsing [1]. The `upload.aspx` component can be leveraged to facilitate this?id=CVE-2024-57968?kagi_q=CVE-2024-57968+details.
  • Requirements: Exploitation requires the attacker to be a remote authenticated user [1].
Impact and Access
Successful exploitation allows an attacker to place files in locations where they can be accessed or executed by the web server or other users. In the context of the XE Group's attacks, this capability was used to deploy webshells, providing the attackers with persistent access to the compromised IIS server [2].
Availability of Exploits and Detection
While specific public exploit code may not be widely distributed, the vulnerability was used as a zero-day by a threat actor. Detection rules (such as Sigma rules) have been developed to identify activity associated with the XE Group's exploitation of this vulnerability [3].
Affected Versions and Mitigation
  • Affected Versions: Advantive VeraCore versions before 2024.4.2.1 [1].
  • Mitigation: Users are advised to update to version 2024.4.2.1 or later to remediate the flaw. Organizations should also consult CISA’s Known Exploited Vulnerabilities (KEV) Catalog for further guidance and requirements regarding this CVE [1].

Sources

  1. CVE-2024-57968 Detail - NVD

    Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders. ... An official website of the United States government Here's how you know ... CVE-2024-57968 Detail. Description. Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to…

  2. Cybercrime gang exploited VeraCore zero-day vulnerabilities for ...

    Cybercriminal outfit XE Group has been quietly exploiting zero-day vulnerabilities (CVE-2025-25181, CVE-2024-57968) in VeraCore software. ... Cybercriminal outfit XE Group has been quietly exploiting zero-day vulnerabilities (CVE-2025-25181, CVE-2024-57968) in VeraCore software.Exploitation of VeraC…

  3. XE Group Activity Detection: From Credit Card Skimming to ...

    Detect XE Group activity using CVE-2024-57968 and CVE-2025-25181, zero-day exploits in VeraCore, with Sigma rules from SOC Prime Platform.